Choosing a GDPR transfer tool: DPF, SCCs, or both
When a restricted transfer actually happens, which mechanism covers it, and when self-certifying to the Data Privacy Framework is worth it.
Quick decision helper
Not sure whether GDPR's international transfer rules apply to your data flow? Answer one question about how the data moves.
How does personal data from people in the EU, UK, or Switzerland reach your organization?
When you need a transfer tool
GDPR Chapter V (Articles 44 to 49) says that when personal data moves from an organization subject to GDPR to a different organization in a third country (outside the EU/EEA), the flow needs a lawful transfer mechanism. Not every EU data flow is such a “restricted transfer”: a person submitting their own data to your site is not one (see Is data entered on our site by an EU visitor a transfer?). But when one organization hands data to another across the border, you need a tool for that hop.
The options
| Mechanism | GDPR article | What it is |
|---|---|---|
| Adequacy | Article 45 | The European Commission declares a destination adequate. For the US, adequacy covers only organizations on the EU-US Data Privacy Framework (DPF) list. |
| Appropriate safeguards | Article 46 | Contract-based protections, most commonly standard contractual clauses (SCCs): pre-approved contract terms signed between exporter and importer. Binding corporate rules (BCRs) fit here too for intra-group transfers. |
| Derogations | Article 49 | Narrow exceptions (explicit consent, contract necessity). Not suitable for routine, systematic flows. |
The practical decision for most US organizations is DPF listing, SCCs, or both. Which one fits depends on which side of the transfer you sit on.
If you are the importer
An EU, UK, or Swiss company (a customer, affiliate, or vendor) sends personal data to you in the US. The sender is the exporter and needs a valid tool covering you:
- You self-certify to the DPF. The exporter can then rely on adequacy: they verify your listing is active and covers the right data types, and no per-flow contract is needed for the transfer itself.
- You sign SCCs with each exporter. Works without any certification, but it is per-relationship paperwork, and exporters must do a transfer impact assessment alongside it.
DPF is most useful in exactly this position: one public listing instead of clauses with every counterparty, and some EU partners simply prefer adequacy. It is a voluntary US Department of Commerce self-certification with real obligations (public commitment to the DPF Principles, an independent recourse mechanism, annual re-certification and fees), so certify only if the transfer benefit is worth standing behind.
If you are the exporter
You are subject to GDPR for some processing and you hand personal data to processors or vendors outside the EU/EEA. That includes vendors in your own country: a US company passing EU customer data to a US processor is still making a restricted transfer, because the receiver is a different organization in a third country, even though no border is crossed. Either way, the fix is on the vendor side, not yours:
- Confirm the vendor is on the DPF list and the listing covers the data you send, or
- Sign SCCs with the vendor (many large processors bake them into their standard data processing agreements, so accepting the vendor’s terms covers it).
Remember the transfer tool is only half the vendor paperwork: any processor also needs an Article 28 data processing agreement, wherever it sits. Do we need a DPA, a transfer tool, or both? walks through the full stack and how it gets signed in practice.
Your own DPF certification does not cover this direction. A common mistake is a US company self-certifying because “we use EU data,” when its actual restricted transfers are outbound to vendors and are already covered by the vendors’ own SCCs or listings.
One wrinkle for the same-country case: the 2021 SCCs only work when the importer is not itself subject to GDPR for that processing. When your processor is also caught by GDPR (common when it processes data for your EU-facing service), the European Commission’s dedicated SCC set for that scenario has been promised since 2022 but not yet adopted. In practice the processor’s DPF listing is the cleanest cover for that hop; otherwise this is a question for counsel.
Where to find the SCCs
GDPR does not contain the clauses itself. Article 46(2)(c) authorizes the European Commission to adopt them, and the current set dates from June 2021. It is one modular document: you pick the module matching the roles on each side of the hop (controller to controller, controller to processor, processor to processor, or processor to controller), fill in the annexes, and sign. The text cannot be edited, though it can be included in a larger contract.
- The European Commission’s SCC page hosts the clauses as downloadable documents, plus the Commission’s questions and answers.
- Implementing Decision (EU) 2021/914 on EUR-Lex is the legal instrument; the clauses are its annex.
Do not confuse them with the Commission’s standard clauses for controller-processor contracts (Decision 2021/915). Those cover Article 28 processor agreements and are not a transfer tool, despite the similar name.
The UK and Switzerland have their own versions: the UK uses the ICO’s international data transfer agreement or addendum, and Switzerland accepts the EU SCCs with adaptations notified to the FDPIC, the Swiss data protection authority.
Practical guidance
- Map first, certify later. Identify each organization-to-organization hop that leaves the EU/EEA (and the UK and Switzerland, which run parallel regimes) before choosing tools.
- Default to SCCs; add DPF when it earns its keep. SCCs work for any eligible counterparty. DPF pays off when you import from many EU senders, or partners ask for list status.
- Do not treat DPF as a GDPR compliance certificate. It is one transfer mechanism, not a substitute for notices, individual rights, security, and processor contracts.
- Keep a fallback for critical flows. EU-US adequacy has been struck down twice before (Safe Harbor, Privacy Shield) and the DPF adequacy decision is periodically reviewed. Many organizations run DPF with SCCs as backup so one court ruling does not break their transfers.
Published August 12, 2026.